CVE-2026-80183
Last modified
CVE-2026-80183 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. With include_names, the response discloses the names and home-domain IDs of every user, group, project, and role involved. The literal "default" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of "None" in list_role_assignments_for_tree.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| OpenStack | Keystone | >= 16.0.0, < 27.0.3; >= 28.0.0, < 28.0.3; >= 29.0.0, < 29.0.3 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-80183?
How severe is CVE-2026-80183?
How do I fix CVE-2026-80183?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-80158A flaw was found in the ipa_getkeytab module of the communit…5.5
- CVE-2026-8016Use after free in WebRTC in Google Chrome prior to 148.0.777…8.8
- CVE-2026-8017Side-channel information leakage in Media in Google Chrome p…3.1
- CVE-2026-80179A flaw was found in jwcrypto. A remote attacker can send a s…5.9
- CVE-2026-8018Insufficient policy enforcement in DevTools in Google Chrome…8.1
- CVE-2026-80182In OpenStack Keystone before 29.0.3, tokens obtained via OAu…7.6
- CVE-2026-80184In OpenStack Keystone before 29.0.3, tokens obtained via del…7.6
- CVE-2026-80185BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRe…5.7
- CVE-2026-80186A stack-based buffer overflow vulnerability exists in BlueZ,…7.6
- CVE-2026-80189LeafWiki extracts an uploaded ZIP archive without limiting h…6.5
- CVE-2026-8019Insufficient policy enforcement in WebApp in Google Chrome p…5.4
- CVE-2026-80192@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.…8.1
Are you affected by CVE-2026-80183?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
